Amazon API Gateway
by Amazon Web Services, Inc. · API Management
Fully managed AWS service for creating, publishing and securing REST, HTTP and WebSocket APIs.
Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.
- Works with
SAP- Deployment
- Cloud
- Pricing
- Pay-as-you-go, per API call plus data transfer
- Founded
- 1994
- Headquarters
- Seattle, Washington, United States
Overview
Amazon API Gateway is a fully managed AWS service for creating, publishing, maintaining, monitoring and securing APIs at any scale, acting as a front door for applications to access backend data, business logic or functionality. It is one of AWS core application-integration services and is commonly paired with AWS Lambda, Amazon Cognito and Amazon CloudWatch.
The service supports three API types: REST APIs (full-featured, with edge-optimized or regional deployment), HTTP APIs (a lighter-weight, lower-cost option optimized for serverless and HTTP backends, described by AWS as up to 71 percent cheaper than REST APIs), and WebSocket APIs for real-time, two-way communication such as chat applications or streaming dashboards. Core capabilities include traffic management, CORS support, authorization and access control via IAM, Lambda authorizers or Amazon Cognito, request throttling, monitoring through CloudWatch, and API versioning.
API Gateway is not an ERP-specific product. AWS publishes reference architectures for using it alongside services such as AWS AppFlow, AWS Glue and AWS Lambda to extract data from SAP systems, including a documented pattern for landing SAP IDocs in Amazon S3 via API Gateway with Lambda-authorizer or Cognito-based authentication, as part of AWS broader SAP Data Integration and Management guidance. These are integration patterns rather than a certified, out-of-the-box SAP connector.
Screenshots & demo
Demo video from the vendor's YouTube channel.
Features & capabilities
API Types
Purpose-built options for different workload shapes.
- REST APIs with edge-optimized or regional deployment
- HTTP APIs optimized for serverless and HTTP backends, up to 71% cheaper than REST APIs per AWS
- WebSocket APIs for real-time two-way communication such as chat or streaming dashboards
- Private APIs accessible only within a VPC via AWS PrivateLink
Traffic and Access Management
Controls for how requests reach backends.
- Request throttling and usage plans
- CORS support
- API versioning and stage management
- Custom domain names and base path mapping
- Canary release deployments
Security and Authorization
Multiple authorization models depending on the caller.
- AWS IAM-based authorization
- Amazon Cognito user pool authorizers
- Custom AWS Lambda authorizers, token- or request-based
- Resource policies for private API access control
Monitoring and Integration
Observability and native AWS service integration.
- Amazon CloudWatch metrics and logging
- AWS X-Ray tracing integration
- Native integration with AWS Lambda for serverless backends
- AWS WAF integration for request filtering
Common use cases
- Exposing AWS Lambda functions as REST or HTTP APIs for serverless applications
- Building real-time chat or live-dashboard applications on WebSocket APIs
- Landing SAP IDoc data into Amazon S3 through a documented API Gateway plus Lambda-authorizer pattern
- Fronting containerized or EC2-hosted backend services with a managed API layer
- Enforcing throttling, usage plans and API keys for third-party or partner API consumers
- Migrating from edge-optimized REST APIs to lower-cost HTTP APIs for HTTP-only backends
Strengths & considerations
Strengths
- Deep native integration with the rest of AWS, including Lambda, Cognito, CloudWatch, WAF and PrivateLink, rather than a standalone gateway
- Three purpose-built API types (REST, HTTP, WebSocket) instead of a one-size-fits-all proxy model
- Pay-as-you-go pricing with no minimum fees, plus a lower-cost HTTP API tier for serverless-only workloads
- AWS-published reference architectures for SAP data extraction patterns such as IDoc-to-S3 via API Gateway
ERP integrations
AWS publishes a pattern for landing SAP IDocs into Amazon S3 via API Gateway, secured with Lambda authorizers or Amazon Cognito, as part of AWS broader SAP Data Integration and Management guidance
Pricing
REST APIs cost 3.50 dollars per million requests plus 0.09 dollars per GB data transfer out. WebSocket APIs cost 1.00 dollar per million messages plus 0.25 dollars per million connection minutes. New AWS customers get a 12-month free tier of 1 million REST API calls, 1 million HTTP API calls, and 1 million WebSocket messages plus 750,000 connection minutes per month. Get an independent shortlist with pricing guidance below.
Technical & security
- Hosting
- Fully managed AWS service, multi-tenant, with regional or edge-optimized deployment
- Compliance
- SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA
About the vendor
- Founded
- 1994
- Headquarters
- Seattle, Washington, United States
- Ownership
- Public (Amazon.com, Inc.; NASDAQ: AMZN)
Alternatives to Amazon API Gateway in API Management
Amazon API Gateway — frequently asked questions
What types of APIs does Amazon API Gateway support?
Three types: REST APIs (full-featured, edge-optimized or regional), HTTP APIs (a lighter-weight, lower-cost option for serverless and HTTP backends, up to 71% cheaper than REST APIs per AWS), and WebSocket APIs for real-time two-way communication.
How is Amazon API Gateway priced?
Pay-as-you-go with no minimum fees. HTTP APIs start at 1.00 dollar per million calls for the first 300 million per month, then 0.90 dollars per million. REST APIs cost 3.50 dollars per million requests plus data transfer. WebSocket APIs cost 1.00 dollar per million messages plus 0.25 dollars per million connection minutes. New AWS customers get a 12-month free tier.
Does Amazon API Gateway have a built-in SAP connector?
No dedicated connector. AWS publishes reference architectures, including a pattern for landing SAP IDocs into Amazon S3 via API Gateway secured with Lambda authorizers or Amazon Cognito, as part of its broader SAP Data Integration and Management on AWS guidance.
What compliance certifications does Amazon API Gateway have?
It is in scope for SOC 1, SOC 2, SOC 3, PCI DSS and HIPAA, among other AWS compliance programs; detailed reports are available through AWS Artifact.
What AWS services does API Gateway typically integrate with?
It is most commonly paired with AWS Lambda for serverless backends, Amazon Cognito for user authentication, Amazon CloudWatch for monitoring, and AWS WAF for request filtering.
Evaluating API Management?
Tell us your ERP and requirements and we'll send an independent shortlist — including Amazon API Gateway and the best-fit alternatives — with honest pros and cons.